OSV 1.4.0 · github-reviewed · 修改于 2021-10-21 22:15
发布时间
2021-09-03 01:08
GitHub 审查时间
2021-08-20 04:13
NVD 发布时间
2021-08-17 23:15
源文件
advisories/github-reviewed/2021/09/GHSA-c32w-3cqh-f6jx/GHSA-c32w-3cqh-f6jx.json
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for a forgotten password.